Network Regulator Automates IoT Device Security and Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of Internet of Things (IoT) devices connected to networks poses a significant security threat due to malware risks, and managing these devices securely and configuring them is challenging, especially for non-technical users, as each device often requires distinct settings and configurations.

Innovation Solution

A network regulator system that detects client devices, intercepts requests, determines device types, and performs security actions tailored to each device, using a hardware processor and memory to manage network addresses and provide security services, including malware protection and device management, by integrating with routers and remote servers for centralized threat detection and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If each IoT device uses distinct configuration interfaces and separate connection settings, then device-specific functionality is optimized, but device management complexity increases significantly

Engineering Contradiction:
Improvedevice-specific configurationVSAvoiddevice management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a network regulator as an intermediary device that automatically detects client devices on the network, determines their device types, and assigns appropriate security policies and configurations. This mediator eliminates the need for users to manually configure each device individually, thereby reducing management complexity while maintaining device-specific optimization.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables devices to automatically register themselves with the network regulator, which then autonomously performs device detection, type determination, and configuration assignment. This self-service mechanism allows devices to be configured automatically without human intervention, solving the contradiction between customized configuration and management simplicity.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual device configuration and security setup is required for each device, then security policies can be precisely tailored, but ease of operation deteriorates for non-technical users

Engineering Contradiction:
Improvesecurity policy precisionVSAvoiduser-friendliness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The network regulator automatically performs device detection, type determination, and security policy assignment without requiring user intervention. Devices autonomously register themselves, and the system autonomously configures appropriate security measures, making the process as easy as plugging in a device while maintaining precise security tailoring.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors network traffic and device behavior, automatically adjusting security policies based on detected threats and device characteristics. This feedback mechanism ensures that security policies remain precisely tailored to actual device needs and threat landscapes without requiring manual reconfiguration by users.

Inventive Principle:
Principle #23Feedback

3Reliability

If a network regulator intercepts and monitors all client requests, then security protection is enhanced, but network processing overhead increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidnetwork processing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The network regulator implements selective monitoring and interception, focusing security resources on specific devices, traffic patterns, or threat types rather than uniformly processing all network traffic. This localized approach enhances security protection where needed while reducing unnecessary processing overhead for low-risk traffic.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs security interception and analysis at appropriate levels of depth based on risk assessment, device type, and traffic characteristics. For low-risk traffic, minimal inspection is performed, while high-risk traffic receives more thorough analysis. This partial action approach balances security enhancement with processing efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11706051B2Systems and methods for automatic device detection, device management, and remote assistance
Publication Date: 2023.07.18 BITDEFENDER IPR MANAGEMENT
  • US11706051B2 patent drawing
  • US11706051B2 patent drawing
  • US11706051B2 patent drawing

AI summary

In some embodiments, a network regulator device protects a local network of client systems (e.g. Internet-of-things devices such as smartphones, home appliances, wearables, etc.) against computer security threats. When introduced to the local network, some embodiments of network regulator take over some network services from a router, and automatically install the network regulator as gateway to the local network. The network regulator then carries out an automatic device discovery procedure and distribute device-specific utility agents to the protected client systems. An exemplary utility agent detects when its host device has left the local network, and in response, sets up a virtual private network (VPN) tunnel with a security server to maintain protection of the respective device.